ThreatCluster
About Blog Help Contact
Login
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Cluster #1862

US Authorities Seize $1m from BlackSuit Ransomware Group

Threat Score:
70
12 articles
100.0% similarity
4 days ago
JSON CSV Text STIX IoCs
Splunk Elastic Sentinel Sigma YARA All Queries

Article Timeline

12 articles
Click to navigate
Aug 11
Aug 11
Aug 11
Aug 12
Aug 12
Aug 12
Aug 12
Aug 12
Aug 12
Aug 13
Aug 13
Aug 13
Oldest
Latest

Key Insights

1
U.S. law enforcement seized $1,091,453 in cryptocurrency linked to the BlackSuit ransomware group, highlighting a coordinated international effort involving agencies from the U.S., U.K., Germany, and others.
2
BlackSuit ransomware, previously known as Royal, has extorted over $370 million from victims across various sectors, including healthcare and education, since its emergence in 2022.
3
The takedown operation on July 24, 2025, resulted in the seizure of four servers and nine domains, significantly disrupting the group's operational capabilities.
4
The cryptocurrency seized was part of a ransom payment made by a victim on April 4, 2023, who paid 49.3 Bitcoin, valued at approximately $1.45 million at that time.
5
Officials noted that BlackSuit's operations included sophisticated tactics such as phishing campaigns and exploitation of vulnerabilities in outdated software, with over 450 known attacks in the U.S.
6
Despite the disruption, experts warn that the operators behind BlackSuit retain the skills and funding to potentially re-emerge under new identities.

Threat Overview

In a significant law enforcement operation, the U.S. Department of Justice announced the seizure of cryptocurrency and server infrastructure associated with the BlackSuit ransomware group, also known as Royal. The operation, which occurred on July 24, 2025, was a coordinated effort involving multiple domestic and international agencies, including the FBI, the U.S. Secret Service, and counterparts from the U.K., Germany, Ireland, France, Canada, Ukraine, and Lithuania. The operation resulted in the confiscation of over $1 million in cryptocurrency, specifically $1,091,453, which was traced back to ransom payments made by victims. 'This operation is the result of tireless international coordination and shows our collective resolve to hold ransomware actors accountable,' stated a representative from the Department of Justice. The seized cryptocurrency was linked to a ransom payment made on April 4, 2023, when a victim paid 49.3 Bitcoin, valued at approximately $1.45 million at the time, in exchange for a decryptor. The BlackSuit group has been responsible for over 450 attacks against U.S. entities, particularly targeting critical infrastructure sectors such as healthcare and education, and has extorted more than $370 million since its inception in 2022.

The BlackSuit ransomware operates through a combination of phishing campaigns, exploitation of Remote Desktop Protocol (RDP), and leveraging vulnerabilities in outdated software systems. This multi-faceted attack approach enables lateral movement within victim networks, facilitating data exfiltration prior to encryption. Experts have noted that ransomware groups like BlackSuit often employ 'big-game hunting' tactics, targeting high-profile organizations to maximize ransom demands, which can range from $1 million to $10 million, with the largest known demand reaching $60 million.

The operation, referred to as 'Operation Checkmate,' not only dismantled the operational infrastructure of BlackSuit but also seized four servers and nine domains, crippling the group's ability to execute further attacks. Despite this disruption, cybersecurity analysts caution that the core operators of BlackSuit possess the expertise and resources to re-establish their operations under new identities. 'Without arrests, the operators behind BlackSuit still have the skills, infrastructure know-how, and hundreds of millions in funding to restart operations under a new name,' noted a cybersecurity analyst.

In response to the increasing threat posed by ransomware groups, experts recommend that organizations implement robust security measures, including regular software updates, employee training on phishing detection, and enhanced monitoring of network traffic to identify suspicious activities. 'Disrupting ransomware infrastructure is not only taking down servers – it’s dismantling the entire ecosystem that enables cyber criminals to operate with impunity,' added Michael Prado, deputy assistant director of the Cyber Crimes Center at Homeland Security Investigations.

Tactics, Techniques & Procedures (TTPs)

T1566
Phishing - BlackSuit employs phishing campaigns to gain initial access to victim networks [1][3]
T1190
Exploit Public-Facing Application - Attackers exploit vulnerabilities in outdated software to gain access [2][4]
T1071.001
Application Layer Protocol: Web Protocols - Utilization of web-based protocols for command and control [1][5]
T1557
Adversary-in-the-Middle - Exploiting vulnerabilities to intercept communications within targeted networks [2][4]
T1059.007
JavaScript/JScript - Use of JavaScript for executing malicious scripts during attacks [3][5]
T1005
Data from Local System - Exfiltration of sensitive data prior to encryption [4][5]
T1053
Scheduled Task/Job - Persistence mechanisms to maintain access to compromised systems [3][5]

Timeline of Events

2022
BlackSuit ransomware group emerges, quickly becoming a significant threat to critical infrastructure [1]
2023-04-04
A victim pays 49.3 Bitcoin to BlackSuit in exchange for a decryptor [3]
2024-01-09
U.S. authorities freeze $1,091,453 in cryptocurrency linked to BlackSuit [2]
2025-06-21
Evidence collected by the U.S. Attorney's Office for the Eastern District of Virginia leads to planned takedown [4]
2025-07-24
Operation Checkmate executed, resulting in the seizure of four servers and nine domains [5]
2025-08-11
U.S. Department of Justice announces the seizure and unseals the warrant [6]

Source Citations

expert_quotes: {'DOJ official': 'Article 5', 'Michael Prado, HSI': 'Article 11', 'Cybersecurity analyst': 'Article 12'}
primary_findings: {'Victim payment details': 'Articles 3, 9, 10', 'Seizure amount and details': 'Articles 1, 3, 6', 'Operational details of BlackSuit': 'Articles 4, 5, 11'}
technical_details: {'Attack methods and infrastructure': 'Articles 1, 2, 5', 'International coordination efforts': 'Articles 6, 10, 12'}
Powered by ThreatCluster AI
Generated 2 days ago
AI analysis may contain inaccuracies

Related Articles

12 articles
1

US Authorities Seize $1m from BlackSuit Ransomware Group

Infosecurity Magazine • 2 days ago

The US Department of Justice has announced the seizure of domains, servers and $1m in proceeds from the BlackSuit ransomware group

Score
66
100.0% similarity
Read more
2

BlackSuit ransomware gang taken down in latest law enforcement sting – but members have already formed a new group

IT Pro Security • 2 days ago

The notorious gang has seen its servers taken down and bitcoin seized, but may have morphed into a new group called Chaos

Score
62
100.0% similarity
Read more
3

U.S. government seized $1 million from Russian ransomware gang

TechCrunch • 4 days ago

A global law enforcement coalition targeted the infrastructure of the group behind the Royal and BlackSuit ransomware strains, allegedly responsible for extorting victims out of $370 million since 2022.

Score
60
100.0% similarity
Read more
4

Law Enforcement Seizes BlackSuit Ransomware Servers Targeting U.S. Critical Infrastructure

GB Hackers • 3 days ago

Law Enforcement Seizes BlackSuit Ransomware Servers Targeting U.S. Critical Infrastructure The U.S. Department of Justice, in collaboration with multiple domestic and international law enforcement agencies, announced the seizure of critical infrastructure associated with the BlackSuit ransomware group, formerly known as Royal. This multi-agency effort, led by the Department of Homeland Security’s Homeland Security Investigations (HSI), the U.S. Secret Service, IRS Criminal Investigation (IRS-CI)

Score
60
100.0% similarity
Read more
5
US reveals it seized $1 million worth of Bitcoin from Russian BlackSuit ransomware gang

US reveals it seized $1 million worth of Bitcoin from Russian BlackSuit ransomware gang

Graham Cluley • 3 days ago

The United States Department of Justice has revealed that the recenttakedownof the BlackSuit ransomware gang's servers, domains, and dark web extortion site, also saw the seizure of US $1,091,453 worth of cryptocurrency. TheDOJ's press releasedescribes how law enforcement agencies around the world - including the United States, UK, Canada, Germany, Ireland, and France - joined forces in an operation to seize four servers and nine domains associated with the gang behind the BlackSuit ransomware o

Score
58
100.0% similarity
Read more
6
BlackSuit Ransomware Takes an Infrastructure Hit From Law Enforcement

BlackSuit Ransomware Takes an Infrastructure Hit From Law Enforcement

Dark Reading • 4 days ago

Vulnerabilities & Threats Cyber Risk Cyberattacks & Data Breaches News BlackSuit Ransomware Takes an Infrastructure Hit From Law EnforcementBlackSuit Ransomware Takes an Infrastructure Hit From Law EnforcementBlackSuit Ransomware Takes an Infrastructure Hit From Law Enforcement A swarm of US agencies joined with international partners to take down servers and domains and seize more than $1 million associated with BlackSuit (Royal) ransomware operations, a group that has been a chronic, persisten

Score
56
97.0% similarity
Read more
7
US govt seizes $1 million in crypto from BlackSuit ransomware gang

US govt seizes $1 million in crypto from BlackSuit ransomware gang

BleepingComputer • 3 days ago

US govt seizes $1 million in crypto from BlackSuit ransomware gang Bill Toulas August 12, 2025 12:18 PM 0 The U.S. Department of Justice (DoJ) seized cryptocurrency and digital assets worth $1,091,453 at the time of confiscation, on January 9, 2024, from the BlackSuit ransomware gang. The authorities tracked the crypto as the cybercriminals moved it repeatedly across virtual currency exchange accounts, depositing and withdrawing it to obfuscate the trace. Eventually, the amount was frozen when i

Score
56
100.0% similarity
Read more
8
BlackSuit ransomware crew loses servers, domains, and $1m in global shakedown

BlackSuit ransomware crew loses servers, domains, and $1m in global shakedown

The Register Security • 3 days ago

Cyber-crime BlackSuit ransomware crew loses servers, domains, and $1m in global shakedown US cops yank servers, domains, and crypto from the Russia-linked gang - but the crooks remain at large In a display of bureaucratic bravado, US law enforcement agencies say they've “disrupted” the BlackSuit ransomware gang (also known as Royal), freeing millions of dollars in virtual currency from its clutches. On July 24, the US Department of Homeland Security Investigations (HSI) - with help from the FBI,

Score
55
100.0% similarity
Read more
9

BlackSuit Ransomware Servers Attacking U.S. Critical Infrastructure Seized by Law Enforcement Seizes

Cybersecurity News • 3 days ago

In a coordinated international operation, law enforcement agencies successfully dismantled critical infrastructure belonging to the BlackSuit ransomware group, also known as Royal, marking a significant victory in the ongoing battle against cybercriminal enterprises. The July 24, 2025 takedown operation resulted in the seizure of four servers, nine domains, and approximately $1.09 million in laundered cryptocurrency […]

Score
54
100.0% similarity
Read more
10

Justice Department Announces Coordinated Disruption Actions Against BlackSuit (Royal) Ransomware Operations

Databreaches • 4 days ago

Law Enforcement Seizes Servers, Domains, and Approximately $1 Million In Laundered Proceeds Owned By BlackSuit (Royal) Ransomware August 11, 2025 The Justice Department announced today coordinated actions against the BlackSuit (Royal) Ransomware group which included the takedown of four servers and nine domains on July 24, 2025. The takedown was conducted by the Department of... Source

Score
53
97.0% similarity
Read more
11

BlackSuit ransomware payment recovered in takedown operation

Computer Weekly IT Security • 2 days ago

Over a million dollars’ worth of cryptocurrency assets laundered by or on behalf of the notorious BlackSuit ransomware gang – previously known as Royal – were seized ahead of a multinational takedown operation in July, led by the US authorities with support from the UK’s National Crime Agency (NCA) and cyber cops from Canada, France, Germany, Ireland, Lithuania and Ukraine. GPT.display('halfpage') GPT.display('mu-1') Operation Checkmate, which took place on 24 July, saw a coordinated action that

Score
52
100.0% similarity
Read more
12

BlackSuit Ransomware’s Infrastructure Dismantled; Crypto Worth $1M Seized

The Cyber Express • 3 days ago

The Department of Justice—backed by the FBI, U.S. Secret Service, Homeland Security Investigations (HSI), IRS Criminal Investigation, and a web of international partners—took decisive action on July 24, executing a coordinated takedown of the BlackSuit ransomware network. This included seizing four servers, shutting down nine domains, and confiscating over $1 million in cryptocurrency, according to a press release published on August 11. BlackSuit, previously known as Royal, rose from the ashes

Score
49
100.0% similarity
Read more

Save to Folder

Choose a folder to save this cluster:

Cluster Intelligence

Key entities and indicators for this cluster

RANSOMWARE
BlackSuit
Royal
MITRE ATT&CK
T1566
T1059
T1053
T1005
T1557
AGENCIES
Department of Justice
Homeland Security Investigations
U.S. Department of Justice
DHS
Department of Homeland Security
COUNTRIES
Lithuania
United Kingdom
United States
Ukraine
Ireland
ATTACK TYPES
Phishing
Double Extortion
Data Exfiltration
RDP Exploitation
Exploitation
INDUSTRIES
Education
Healthcare
Energy
Public Safety
Critical Infrastructure
CLUSTER INFORMATION
Cluster #1862
Created 4 days ago
Semantic Algorithm

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration